Техническая информация
- '%PROGRAM_FILES%\ttyingyin\setupX_052.exe'
- '%PROGRAM_FILES%\ttyingyin\app.exe'
- '%PROGRAM_FILES%\ttyingyin\setupX_052.exe' (загружен из сети Интернет)
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\tongjiGateway[1].php
- %TEMP%\nsz3.tmp\reply.htm
- %TEMP%\nsz3.tmp\System.dll
- %TEMP%\nsz3.tmp\inetc.dll
- %TEMP%\nsz3.tmp\NSISdl.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\guanggao[1].htm
- %PROGRAM_FILES%\ttyingyin\CKCleaner_silent_t004.exe
- %PROGRAM_FILES%\ttyingyin\setupX_052.exe
- %PROGRAM_FILES%\ttyingyin\logo.ico
- %HOMEPATH%\Start Menu\Programs\МмМмУ°Тф\МмМмУ°Тф.lnk
- %TEMP%\nsw2.tmp
- %PROGRAM_FILES%\ttyingyin\app.exe
- %HOMEPATH%\Start Menu\Programs\МмМмУ°Тф\Р¶ФШ МмМмУ°Тф.lnk
- %PROGRAM_FILES%\ttyingyin\uninst.exe
- %TEMP%\nsz3.tmp\xID.dll
- %HOMEPATH%\Desktop\МмМмУ°Тф.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МмМмУ°Тф.lnk
- 'www.ht##f.com':80
- 'do#####.caiyunstat.com':80
- 'www.sy##zx.com':80
- 'ch####hi.32so.com':80
- 'localhost':1038
- www.ht##f.com/guanggao.htm
- do#####.caiyunstat.com/soft/update/24/1.0/CKCleaner_silent_t004.exe
- ch####hi.32so.com/tongjiGateway.php?id########################################
- www.sy##zx.com/setupX_052.exe
- DNS ASK www.ht##f.com
- DNS ASK do#####.caiyunstat.com
- DNS ASK ch####hi.32so.com
- DNS ASK www.sy##zx.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'